Interview question
Why do you want to work in threat intelligence rather than another security discipline?
A motivation question with a technical subtext: the interviewer is checking whether you know what the job actually involves day to day, or whether you are picturing a more exciting version of it.
What a strong answer covers
- Shows an accurate picture of the work: research, writing, stakeholder communication, and a large amount of processing and enrichment.
- Gives a specific and personal reason rather than a generic interest in cyber security.
- Demonstrates existing engagement — reading finished intelligence, tracking an actor, writing analysis, a home lab.
- Acknowledges the unglamorous parts honestly, especially the volume of writing.
- Connects the motivation to something the interviewer can verify or ask a follow-up about.
Expert answer
A strong answer has three parts: an accurate picture of the work, a specific personal reason, and evidence you have already been doing some of it.
On the work: intelligence is a research and communication job. A realistic week involves triaging collection, enriching a few clusters of activity, mapping behaviour to a framework, and writing — a lot of writing — for people who are not in the SOC. Candidates who describe the role as "hunting APTs" tend to be describing a version of the job that does not exist.
On the reason: something specific carries more weight than a general interest in security. Preferring the analytic side to the operational one, wanting to work on the question of why an adversary does something rather than only what they did, or coming from a research or languages background where source evaluation was already the core skill — any of these are credible because they are checkable.
On the evidence: the strongest answers point at something concrete. An intrusion set you have tracked and written about, a Sigma rule you contributed, sustained participation in a sharing community, or a blog post with explicit confidence language. This turns a motivation answer into a demonstration.
Honesty about the parts that are tedious is a plus, not a risk. Interviewers have all done the processing work and know it dominates the early years.
Mistakes that cost candidates points
- A generic "I have always been passionate about cyber security" with nothing specific behind it.
- Describing the job as mostly technical analysis and omitting the writing entirely.
- Naming a famous APT report as the whole motivation without any personal work to point to.
- Framing CTI as a stepping stone to something else, which answers a different question than the one asked.
You have read the answer, which is the easy part. Answer it in your own words and get graded against this same rubric, with the follow-up probe an interviewer would ask next.
Go deeper
Related questions
- What is cyber threat intelligence, and how is it different from a threat feed?
- A senior analyst has written an assessment you think is wrong. It is going out to the CISO tomorrow. What do you do?
- What threat intelligence do you read regularly, and how do you decide whether to believe a vendor report?
- Explain the difference between tactical, operational and strategic threat intelligence, with an example of each.
- A board member asks you what your team does and why it is worth the budget. You have two minutes. What do you say?